Fortinet Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Fortinet products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

34

In CISA KEV

29

Beyond CISA KEV

5

Sensor Observed

3

Virtual Patch Available

2

Fortinet KEVs Added by Year

Loading...

34 Fortinet KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2022-42475

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0...

Confirmed In CISA 13 Dec 2022
CVE-2022-41328

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through...

Confirmed In CISA 14 Mar 2023
CVE-2023-27997

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below,...

Confirmed In CISA 13 Jun 2023
CVE-2024-21762

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0...

Confirmed In CISA 09 Feb 2024
CVE-2023-48788

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2,...

Confirmed In CISA 25 Mar 2024
CVE-2024-23113

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13,...

Confirmed In CISA 09 Oct 2024
CVE-2024-47575

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7,...

Confirmed In CISA 23 Oct 2024
CVE-2024-55591

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy...

Confirmed In CISA 14 Jan 2025
CVE-2025-24472

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0...

Confirmed In CISA 18 Mar 2025

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 3
  • CWE-288 — Authentication Bypass Using an Alternate Path or Channel 3
  • CWE-787 — Out-of-bounds Write 2
  • CWE-306 — Missing Authentication for Critical Function 2
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
  • CWE-287 — Improper Authentication 2
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology